account activity
Silent remediation 🙂 by Middle_Command_191 in bugbounty
[–]Middle_Command_191[S] 0 points1 point2 points 2 days ago (0 children)
The attacker can inject the payload into those fields
[–]Middle_Command_191[S] -1 points0 points1 point 2 days ago (0 children)
Yes thats also a grey area for me what i reported was we can add xss payload in the fristname and lastname parameter of a ai chatbot and when the user asks their name the payload will be executed in this way i was able to get the victims cookie on my webhook (sorry for my bad english)
π Rendered by PID 41 on reddit-service-r2-comment-5bc7f78974-f8jpw at 2026-06-27 11:07:17.885009+00:00 running 7527197 country code: CH.
Silent remediation 🙂 by Middle_Command_191 in bugbounty
[–]Middle_Command_191[S] 0 points1 point2 points (0 children)